Vulnerabilities > Out-of-bounds Read

DATE CVE VULNERABILITY TITLE RISK
2021-09-05 CVE-2021-40516 Out-of-bounds Read vulnerability in multiple products
WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-bounds read in plugins/relay/relay-websocket.c in the Relay plugin.
network
low complexity
weechat debian CWE-125
7.5
2021-09-03 CVE-2021-23437 Out-of-bounds Read vulnerability in multiple products
The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
network
low complexity
python fedoraproject CWE-125
7.5
2021-09-02 CVE-2021-22790 Out-of-bounds Read vulnerability in Schneider-Electric products
A CWE-125: Out-of-bounds Read vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (part numbers BMXP34*, all versions), Modicon MC80 (part numbers BMKC80*, all versions), Modicon Momentum Ethernet CPU (part numbers 171CBU*, all versions), PLC Simulator for EcoStruxureª Control Expert, including all Unity Pro versions (former name of EcoStruxureª Control Expert, all versions), PLC Simulator for EcoStruxureª Process Expert including all HDCS versions (former name of EcoStruxureª Process Expert, all versions), Modicon Quantum CPU (part numbers 140CPU*, all versions), Modicon Premium CPU (part numbers TSXP5*, all versions).
network
low complexity
schneider-electric CWE-125
6.5
2021-08-26 CVE-2021-30593 Out-of-bounds Read vulnerability in multiple products
Out of bounds read in Tab Strip in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.
network
low complexity
google fedoraproject CWE-125
8.1
2021-08-25 CVE-2021-1588 Out-of-bounds Read vulnerability in Cisco Nx-Os 7.0(3)I7(9)/8.4(1)/9.3(7)
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-125
8.6
2021-08-24 CVE-2021-31002 Out-of-bounds Read vulnerability in Apple Macos 11.6/11.6.1/12.0.0
An out-of-bounds read was addressed with improved input validation.
local
low complexity
apple CWE-125
7.8
2021-08-24 CVE-2021-31013 Out-of-bounds Read vulnerability in Apple Iphone OS and Macos
An out-of-bounds read was addressed with improved bounds checking.
local
low complexity
apple CWE-125
5.5
2021-08-24 CVE-2021-30939 Out-of-bounds Read vulnerability in Apple products
An out-of-bounds read was addressed with improved bounds checking.
local
low complexity
apple CWE-125
7.8
2021-08-24 CVE-2021-30953 Out-of-bounds Read vulnerability in multiple products
An out-of-bounds read was addressed with improved bounds checking.
network
low complexity
apple fedoraproject debian CWE-125
8.8
2021-08-24 CVE-2021-30958 Out-of-bounds Read vulnerability in Apple products
An out-of-bounds read was addressed with improved input validation.
local
low complexity
apple CWE-125
7.8